
NISG 20261 – Critical infrastructure companies are required to step up their defenses against cyberattacks
Introduction
With the NISG 2026, Austria is implementing the requirements of the European NIS2 Directive2 into national law. The Federal Act was promulgated on December 23, 2025, and will enter into force on October 1, 2026.
We aim to provide an initial overview of the key content and objectives of the NISG 2026, without delving into every single detail or specific provision.
Advancing digitalization offers diverse opportunities for the economy and society, but simultaneously leads to an increasing dependence on secure network and information systems. This also increases vulnerability to cyberattacks. Against this backdrop, effective legal and organizational measures to strengthen cybersecurity are required for companies in critical infrastructure.3
The overarching objective of the NISG 2026 is to ensure a high level of cybersecurity in Austria. This is to be guaranteed, in particular, for the essential and important entities mentioned in § 2 of the NISG 2026 and defined in more detail in Annexes 1 and 2.
The term "entity" used by the law encompasses both companies and entities belonging to other legal bodies, such as public institutions, authorities, or associations. In the law, the term "entity" is defined as a natural person or a legal person or registered partnership created and recognized under the national law applicable at its registered office, which can exercise rights and be subject to obligations in its own name.4
The NISG 2026 covers a total of 18 sectors and their associated subsectors (see the appendix to this article), which are essential for the functioning of society and the economy, as well as for the operation of the internal market. The material scope of the NISG 2026 extends to essential and important entities within these sectors and subsectors. The affected entities are required to implement appropriate cybersecurity measures and comply with the reporting and cooperation obligations stipulated by the law (see below for details).
Compared to the previous NISG5, which expires at the end of September 30, 2026, and covered only seven sectors, the NISG 2026 significantly expands its scope. By extending to a total of 18 sectors and subsectors, a much larger group of entities will be subject to legal requirements in the future.
The NISG 2026 distinguishes between essential entities (Annex 1) and important entities (Annex 2).
Companies and other entities falling within the scope of the NISG 2026 are required to ensure an appropriate level of cybersecurity. To this end, they must implement organizational, technical, and operational measures to protect their network and information systems. The essential obligations are set out in the second section of the NISG 2026 and include, in particular, the following measures.
The cybersecurity authority9 maintains a register of essential and important entities. For this purpose, the affected entities must register electronically with the authority and provide specific structured information as required by law10 to be submitted.
The registration must be completed within three months of the NISG 2026 entering into force, i.e., by December 31, 2026 . If an entity only meets the criteria for an essential or important entity after this date, registration must be carried out immediately, and no later than three months after the registration obligation arises.
Essential and important entities must implement appropriate and proportionate technical, operational, and organizational risk management measures. This must be done, in particular, while taking the state of the art into account. Regarding the assessment of "proportionality," particular consideration must be given to (i) the extent of the entity's exposure to risk and its services, (ii) the size of the entity, and (iii) the likelihood of cybersecurity incidents occurring, as well as their severity and impact.
Risk management must follow an all-hazards approach and must, at a minimum, include the minimum measures provided for in the NISG 2026. These include, in particular, measures for risk analysis, the security of network and information systems, the management of cybersecurity incidents, and supply chain security.11
Discretion is therefore limited solely to the specific design of the measures. Whether risk management measures are to be implemented is not at the discretion of the affected entities. Every entity must ensure a level of security that corresponds to its individual risk profile.
The management bodies of essential and important entities are responsible for compliance with and oversight of risk management measures.
Management bodies are defined as those natural persons responsible for the management of the entity at the executive or board level, i.e., managing directors, board members, members of the administrative board, or heads of other types of entities.
This does not include, in particular, authorized signatories (Prokuristen) or persons who exclusively hold the position of Chief Information Security Officer (CISO).12
The NISG 2026 establishes reporting obligations for essential and important entities and sets specific deadlines for these.
Within 12 months from the date the registration obligation for essential and important entities takes effect, these entities must submit information regarding their implemented risk management measures to the cybersecurity authority in a structured format.
Obligation for review by an independent body: Furthermore, the cybersecurity authority may require entities to have the effectiveness of their technical, operational, and organizational measures reviewed by an independent body. As a general rule, the corresponding proof must be provided within two years. For essential entities, shorter deadlines apply regarding operational and organizational measures; these must submit the proof within two months of a request by the authority. An initial request can be made no earlier than two years after the NISG 2026 enters into force.
Essential and important entities are required to report significant cybersecurity incidents without undue delay.
A "significant cybersecurity incident" exists if it causes or is capable of causing severe operational disruption or significant financial loss, or if it causes or is capable of causing significant material or non-material damage to natural or legal persons. When assessing significance, factors to consider include the importance of the affected network and information systems, the severity and technical characteristics of the cyber threat, exploited vulnerabilities, and the entity's experience with similar incidents. In addition, company-specific and sector-specific characteristics must be taken into account where applicable.13
The report must be submitted to the relevant Computer Security Incident Response Team (CSIRT) 14 . If no CSIRT is responsible for the institution in question, the report must be submitted to the national CSIRT, which will forward it immediately to the cybersecurity authority.
The reporting process is carried out in stages: First, an early warning must be submitted within 24 hours of becoming aware of the incident. Within 72 hours , a more comprehensive report must be submitted, which updates the early warning if necessary and includes an initial assessment of the incident, particularly its severity and impact. Upon request by the responsible CSIRT or the cybersecurity authority, interim reports must be submitted during the handling of the incident. A final report must be submitted no later than one month after the comprehensive report. If the incident is still ongoing at that time, a progress report must be submitted instead.
If a significant cybersecurity incident impairs the provision of the services concerned, the recipients of these services must also be informed immediately about the incident and – as far as possible – about appropriate protective and remedial measures.
The NISG 2026 provides for administrative fines for violations of the obligations stipulated therein. District administrative authorities are responsible for conducting administrative penal proceedings. If there is a suspicion of an administrative offense, the cybersecurity authority must report this to the competent district administrative authority.
Administrative criminal liability applies to legal entities and registered partnerships if an administrative offense was committed by a management body or was made possible due to a lack of supervision or control by a management body, but not to the individual member of the management body themselves.
Section 45 of the NISG 2026 regulates which violations constitute administrative offenses. According to paragraph 1, these are:
Item 1: failure to comply with the obligation to provide cybersecurity training for management bodies in accordance with Section 31 (2);
Item 2: failure to comply with the obligation to provide cybersecurity training for employees in accordance with Section 31 (2), second sentence;
Item 3: failure to implement the risk management measures prescribed under Section 32, provided that this fact has not become known to the cybersecurity authority solely on the basis of a self-declaration under Section 33 (1);
Item 4: violation of the obligation to report a significant cybersecurity incident in accordance with Section 34 (1) and (2), as well as the associated reporting obligations;
Item 5: violation of the obligation to immediately inform the recipients of the services of an essential or important entity in accordance with Section 34 (3); and
Item 6: failure to comply with enforcement measures ordered under Section 39 (2) within the specified time limit, provided that there is no liability under another provision of the NISG 2026 for the same underlying facts.
In addition, Section 45 (4) of the NISG 2026 defines further administrative offenses.
Regarding the level of penalties, the law distinguishes between essential and important entities:
For essential entities, the maximum penalty is up to 10 million euros or—if this amount is higher—up to 2% of the total worldwide annual turnover of the company to which the essential entity belongs. For important entities, the maximum penalty is up to 7 million euros or—if this amount is higher—up to 1.4% of the total worldwide annual turnover of the company to which the important entity belongs.
For other administrative offenses under Section 45 (4) of the NISG 2026, fines of up to 50,000 euros are provided, increasing to up to 100,000 euros in the event of a repeat offense. This includes, in particular, failure to register with the cybersecurity authority on time.
The NISG 2026 provides special regulations for public authorities and other public administration bodies. In these cases, the district administrative authority must determine non-compliance with legal obligations by way of an official notice and set a reasonable deadline for restoring a lawful state. If this is not done within the specified time, the non-compliance may be made public under certain conditions. Before publication, however, the respective authority or public body must be given the opportunity to comment within a reasonable period. Publication may only take place to the extent that it does not pose a risk to public order, public security, or national security, and does not adversely affect the legitimate interests of essential and important entities.
The NISG 2026 does not provide for direct administrative fines for management bodies. However, a breach of the duties imposed on them by law can result in civil liability consequences and, in particular, give rise to claims for damages against the respective management body.
Liability of managing directors or board members in recourse for administrative fines imposed on the company is likely not applicable,
However, the damages caused by successful cyberattacks (financial losses to the company itself and its customers, for which the company is liable) and the costs associated with troubleshooting could constitute compensable damages.
A prerequisite for liability for damages is the existence of damage caused unlawfully and culpably that falls within the protective scope of the violated norm. The decisive factor is therefore whether the management body has breached the duties of care incumbent upon it and whether this breach of duty was the cause of the damage incurred. If, on the other hand, a management body cannot be blamed for failing to comply with legal obligations – for example, because the attacker was successful despite reasonable and diligently implemented protective measures, or because the management body lacked the necessary influence or was outvoted regarding an unlawful decision – its liability is excluded.16
The increased responsibility of management bodies for cybersecurity associated with the NISG 2026 makes a clear internal distribution of tasks and responsibilities within the company or other institution even more important in the future. Companies should therefore check whether existing departmental distributions meet the requirements of the NISG 2026 or adjust them accordingly.
Clearly defining responsibilities—especially for cybersecurity and information security—not only improves internal organization and decision-making structures but can also be of significant importance for individual management board members in the event of liability. However, the allocation of departmental responsibilities does not eliminate the governing body's overall legal accountability. Every governing body remains obligated to stay informed about material risks and to appropriately monitor compliance with legal requirements.17
The increased responsibility of governing bodies also means that companies must possess sufficient technical expertise in IT and cybersecurity. In larger companies, in particular, this will regularly require the deployment of qualified IT security professionals or the involvement of external specialists. They support governing bodies in assessing the current state of IT and existing security measures, implementing legal requirements, evaluating risks, and designing appropriate security measures. However, the responsibility for initiating, monitoring, and strategically managing cybersecurity remains with the governing body in these cases as well.
The NISG 2026 fundamentally reshapes and expands the legal framework for cybersecurity in Austria. In particular, the significant expansion of the material scope, the comprehensive risk management and reporting obligations, and the greater involvement of governing bodies lead to significantly higher compliance requirements for companies and institutions falling under the NISG 2026.
Companies should use the remaining time before the law comes into effect to assess whether they are affected, evaluate existing security precautions, and, in particular, implement the necessary organizational and technical measures in a timely manner.
Attention should also be paid to a clear distribution of responsibilities within governing bodies. A clear assignment of responsibilities for IT and cybersecurity creates defined areas of accountability, facilitates the fulfillment of monitoring and control duties, and can be of significant importance in the event of liability, especially for management board members who are not responsible for that specific department.
Likewise, the development of appropriate human resources will increasingly come into focus in the future. Many companies will need to hire qualified IT and cybersecurity staff and/or rely on external specialists to effectively implement the new legal requirements.
Furthermore, cyber risk insurance and D&O insurance should be considered. In the case of D&O insurance in particular, it should be verified whether manager liability arising from cyber-related damage cases is included in or excluded from the insurance coverage.
As the numerous successful cyberattacks by state or state-affiliated actors demonstrate, even government institutions—such as those recently in the USA, Belgium, France, or Liechtenstein—are not immune to successful cyberattacks not immune.
Given the vague legal terms used in the NISG 2026 – such as "proportionality," "level of risk exposure," "likelihood of cybersecurity incidents occurring," and the foreseeable "severity" and "impact" – management must be granted a degree of discretion (interpretative leeway). It would also be a mistake to overvalue predictability and the probability of occurrence from an ex-post perspective, thereby immediately assigning blame (hindsight bias).
I hope that courts will not impose excessive requirements on the accountability of management bodies and will limit the reversal of the burden of proof regulated in the Stock Corporation Act to the necessary cooperation in explaining the measures taken and clarifying damages that have occurred, based on proximity to evidence, rather than imposing corporate risk on the management body personally via the detour of a reversed burden of proof.18
List of the 18 sectors and subsectors
1 Federal Act enacting the Federal Act on Ensuring a High Level of Cybersecurity for Network and Information Systems (Network and Information Systems Security Act 2026 – NISG 2026) and amending the Telecommunications Act 2021 and the Health Telematics Act 2012; Federal Law Gazette I No. 94/2025.
2 Directive (EU) 2022/2555, OJ L 2022/333, 80.
3 308 of the Appendices to the XXVIII. Legislative Period – Government Bill – Explanatory Notes.
4 Section 3 (10) NISG 2026.
5 Federal Act on Ensuring a High Level of Security for Network and Information Systems (Network and Information Systems Security Act – NISG); Federal Law Gazette I 2018/111.
6 See Section 24 (1) (1) NISG 2026 for details.
7 Section 25 NISG 2026.
8 For details, see Section 24 (2) NISG 2026.
9 The NISG 2026 establishes the Federal Office for Cybersecurity as the national cybersecurity authority. It reports directly to the Federal Ministry of the Interior.
10 For details, see Section 29 (2) NISG 2026.
11 For details on the minimum requirements, see Section 32 (4) NISG 2026.
12 308 of the Appendices XXVIII. GP - Government Bill – Explanatory notes on Section 3.
13 308 of the Appendices XXVIII. GP - Government Bill – Explanatory notes on Section 35.
14 To ensure the security of network and information systems, Computer Emergency Response Teams (CERTs) were already established under the NISG.
15 Regarding the possibility of recourse/non-recourse, see J. Reich-Rohrwig/K. Grossmayer in Artmann/Karollus, AktG II6 marginal note 341, 599.
16 308 of the Appendices XXVIII. GP - Government Bill – Explanatory notes on Section 31; J. Reich-Rohrwig/K. Grossmayer in Artmann/Karollus, AktG II6 marginal note 440 et seq.; J. Reich-Rohrwig in Straube GmbHG Section 25 marginal note 325 et seq., 335
17 J. Reich-Rohrwig in Artmann/Karollus AktG II6 § 70 para. 147 et seq., 153.
18 See J. Reich-Rohrwig/K. Grossmayer in Artmann/Karollus, AktG II6 para. 441.